DETAILED ACTION
The following claims are pending in this office action: 17-31
Claims 17, 24-25 and 31 are independent claims.
The following claims are new: 17-31
The following claims are cancelled: 1-16
Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Drawings
The drawings filed on 05/05/2025 are accepted.
Information Disclosure Statement
The information disclosure statement (IDS) submitted on 05/27/2025 has been considered. The submission is in compliance with the provisions of 37 CFR 1.97. Accordingly, an initialed and dated copy of Applicant’s IDS form 1449 filed 05/05/2025 is attached to the instant Office action.
Specification
The title of the invention is not descriptive. A new title is required that is clearly indicative of the invention to which the claims are directed.
Claim Objections
Claims 25-31 are objected to because of the following informalities:
Claims 25-31 recites the limitation “a first serial communication interface” (claim 25, ln. 14; and claim 31, ln. 16). It appears applicant intends to refer to the instance of “a first serial communication interface” already recited. See, for example, in claim 25, ln. 4 and in claim 31, ln. 5. If so, Examiner suggests “the first serial communication interface” instead.
Claims 25-31 recites the limitation “a second cryptography unit” (claim 25, ln. 18; and claim 31, ln. 20-21). It appears applicant intends to refer to instances of a second cryptography unit already recited. See, for example, in claim 25, ln. 7-8 and in claim 31, ln. 8. If so, Examiner suggests “the second cryptography unit” instead.
Claims 25-31 recites the limitation “a second memory device” (claim 25, ln. 20; and claim 31, ln. 22). It appears applicant intends to refer to instances of a second memory device already recited. See, for example, in claim 25, ln. 8 and in claim 31, ln. 9. If so, Examiner suggests “the second memory device” instead.
Claim Interpretation
The following is a quotation of 35 U.S.C. 112(f):
(f) Element in Claim for a Combination. – An element in a claim for a combination may be expressed as a means or step for performing a specified function without the recital of structure, material, or acts in support thereof, and such claim shall be construed to cover the corresponding structure, material, or acts described in the specification and equivalents thereof.
Claims 17-31 invokes 112(f). The following is a list of non-structural generic placeholders that may invoke 35 U.S.C. 112(f): "mechanism for," "module for," "device for," "unit for," "component for," "element for," "member for," "apparatus for," "machine for," or "system for." See MPEP 2181 Sec. I. The claim limitations use the generic placeholder unit.
The claims in this application are given their broadest reasonable interpretation using the plain meaning of the claim language in light of the specification as it would be understood by one of ordinary skill in the art. The broadest reasonable interpretation of a claim element (also commonly referred to as a claim limitation) is limited by the description in the specification when 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is invoked.
As explained in MPEP § 2181, subsection I, claim limitations that meet the following three-prong test will be interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph:
(A) the claim limitation uses the term “means” or “step” or a term used as a substitute for “means” that is a generic placeholder (also called a nonce term or a non-structural term having no specific structural meaning) for performing the claimed function;
(B) the term “means” or “step” or the generic placeholder is modified by functional language, typically, but not always linked by the transition word “for” (e.g., “means for”) or another linking word or phrase, such as “configured to” or “so that”; and
(C) the term “means” or “step” or the generic placeholder is not modified by sufficient structure, material, or acts for performing the claimed function.
Use of the word “means” (or “step”) in a claim with functional language creates a rebuttable presumption that the claim limitation is to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites sufficient structure, material, or acts to entirely perform the recited function.
Absence of the word “means” (or “step”) in a claim creates a rebuttable presumption that the claim limitation is not to be treated in accordance with 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. The presumption that the claim limitation is not interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, is rebutted when the claim limitation recites function without reciting sufficient structure, material or acts to entirely perform the recited function.
Claim limitations in this application that use the word “means” (or “step”) are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action. Conversely, claim limitations in this application that do not use the word “means” (or “step”) are not being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, except as otherwise indicated in an Office action.
This application includes one or more claim limitations that do not use the word “means,” but are nonetheless being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, because the claim limitation(s) uses a generic placeholder (unit) that is coupled with functional language without reciting sufficient structure to perform the recited function and the generic placeholder is not preceded by a structural modifier. Such claim limitations include: a first cryptography unit configured to encrypt the first data to be sent (claims 17, 24-25 and 31); a second cryptography unit configured to decrypt the received encrypted first data (claims 17, 24-25 and 31); the second cryptography unit is configured to encrypt the second data to be sent (claim 18); the first cryptography unit is configured to decrypt the received encrypted second data (claim 18); the second cryptography unit is configured to decrypt a received set of first data (claim 21); the first cryptography unit is configured to decrypt a received set of second data (claim 22); wherein the first cryptography module and the third cryptography module are configured to encrypt data to be sent; the second cryptography module and the fourth cryptography module are configured to decrypt data to be received (claim 22); the second cryptography unit decrypts a received set of first data (claim 29); the first cryptography unit decrypts a received set of second data (claim 30).
Because these claim limitations are being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, they are being interpreted to cover the corresponding structure described in the specification as performing the claimed function, and equivalents thereof. As for the first/second cryptography unit, pg. 2 ln. 27-29 and Pg. 3, ln. 1-10 describes the first and/or second cryptography unit “as a hardware-based cryptography unit.” Furthermore, a special hardware component ... is integrated into corresponding computing units or microcontrollers ... support various encryption algorithms.”
Here it is unclear whether the “hardware-based cryptographic unit” is related to the “special hardware component.” Furthermore, the structure of the “special hardware component” is unclear except that it is “integrated into the corresponding computing units or microcontrollers. Furthermore, even if the “cryptography unit” corresponds to the “special hardware component” it is unclear an algorithm is disclosed for performing the claimed functions as only the algorithms for encryption and decryption are disclosed, and not any algorithm for how the “special hardware component” is programed to interact with the microcontrollers, memory or processors as described. If it is unclear whether there is sufficient supporting structure or whether the algorithm is adequate to perform the entire claimed function, it is appropriate to reject the claim under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph. See MPEP 2181, Section II.B.
As for the first/second/third/fourth cryptography module, no structure at all can be found in the specification for the respective modules. Pg. 6 and pg. 17 recite the respective modules, but only simply recite the claimed function.
If applicant does not intend to have this/these limitation(s) interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph, applicant may: (1) amend the claim limitation(s) to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph (e.g., by reciting sufficient structure to perform the claimed function); or (2) present a sufficient showing that the claim limitation(s) recite(s) sufficient structure to perform the claimed function so as to avoid it/them being interpreted under 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph.
Claim Rejections - 35 USC § 112
The following is a quotation of 35 U.S.C. 112(b):
(b) CONCLUSION.—The specification shall conclude with one or more claims particularly pointing out and distinctly claiming the subject matter which the inventor or a joint inventor regards as the invention.
With respect to claims 17-31 the claim limitations : a first cryptography unit configured to encrypt the first data to be sent (claims 17, 24-25 and 31); a second cryptography unit configured to decrypt the received encrypted first data (claims 17, 24-25 and 31); the second cryptography unit is configured to encrypt the second data to be sent (claim 18); the first cryptography unit is configured to decrypt the received encrypted second data (claim 18); the second cryptography unit is configured to decrypt a received set of first data (claim 21); the first cryptography unit is configured to decrypt a received set of second data (claim 22); wherein the first cryptography module and the third cryptography module are configured to encrypt data to be sent; the second cryptography module and the fourth cryptography module are configured to decrypt data to be received (claim 22); the second cryptography unit decrypts a received set of first data (claim 29); the first cryptography unit decrypts a received set of second data (claim 30) invoke 35 U.S.C. 112(f) or pre-AIA 35 U.S.C. 112, sixth paragraph. However, the written description fails to disclose the corresponding structure, material, or acts for performing the entire claimed function and to clearly link the structure, material, or acts to the function. The specification is unclear as to the corresponding structure for the first/second cryptography units and entirely silent as to the corresponding structure of the of the cryptography modules. Therefore, the claims 17-31 are indefinite and is rejected under 35 U.S.C. 112(b) or pre-AIA 35 U.S.C. 112, second paragraph.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 17-18, 23-26 and 31 are rejected under 35 U.S.C. 103 as being unpatentable over Klapman (US Pub. 2022/0123932) (hereinafter “Klapman”) in view of Luft et al. (US Pub. 2007/0153580) (hereinafter “Luft”).
As per claim 17, Klapman teaches a data processing device for a control device, the data processing device comprising: ([Klapman, para. 0003] “Host computer system ... a server [data processing device] in a data centre [a control device, such as a micro data center]”)
at least a first computing unit and a second computing unit; ([Klapman, para. 0121] “data storage device (DSD) [computing unit as it a device/unit located within the server/computer] ... located within host computer system”; [para. 0150] “two DSDs ... the first DSD .... second DSD”)
wherein the first computing unit includes a first memory device configured to provide first data to be sent, ([Klapman, para. 0122] “DSD ... comprises a controller 206”’; [para. 0150] “Controller 206 ... to send ... encrypted data to the first DSD”) a first cryptography unit configured to encrypt the first data to be sent; and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of an encryption ... algorithm”; [para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data”)
wherein the second computing unit includes a second cryptography unit configured to decrypt the received encrypted first data, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of ... decryption algorithm”; [para. 0150] “The first DSD ... to decrypt the data”) a second memory device which is configured to store the decrypted received first data. ([Para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
Klapman does not clearly teach a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit; and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit.
However, Luft teaches a first serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0070] “The personal computer 101 has a USB interface 103”) configured to send the encrypted first data to be sent from the first computing unit to the second computing unit; and ([Para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
wherein the second computing unit includes a second serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0071] “The USB stick 102 likewise has a USB interface 111”) configured to receive the encrypted first data from the first computing unit. ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit; and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit. One of ordinary skill in the art would have been motivated to make this modification because an attack on the interfaces is made considerably more difficult, or is even prevented. (Luft, para. 0153)
As per claim 18, Klapman in view of Luft teaches claim 17.
Klapman does not clearly teach wherein the second memory device is configured to provide second data to be sent, the second cryptography unit is configured to encrypt the second data to be sent, and the second communication interface is configured to send the encrypted second data to be sent from the second computing unit to the first computing unit, wherein the first communication interface is configured to receive the encrypted second data from the second computing unit, the first cryptography unit is configured to decrypt the received encrypted second data, and the first memory device is configured to store the decrypted received second data.
However, Luft teaches wherein the second memory device is configured to provide second data to be sent, ([Luft, para. 0121] “It should be noted that the transmission can also take place in the opposite direction from the USB stick 102 to the personal computer 101 ... transmitted from the data memory 116 in the USB stick 102 to the data memory 108 in the personal computer 101”) the second cryptography unit is configured to encrypt the second data to be sent, ([para. 0076] “the USB stick 102 have a respective logic unit ... to carry out an asymmetric encryption method”; [para. 0121] “In this case, the encryption is carried out in the USB stick”) and the second communication interface is configured to send the encrypted second data to be sent from the second computing unit to the first computing unit, ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data [encrypted second data] can be transmitted 119 between them”; [para. 0121] “transmission can also take place in the opposite direction from the USB stick 102 [the second communication interface to send] to the personal computer 101 [to the first computing unit] ... transmitted from the data memory 116 in the USB stick 102”) wherein the first communication interface is configured to receive the encrypted second data from the second computing unit, ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, [first communication interface] 111, such that data can be transmitted 119 between them”; [para. 0121] “transmission can also take place in the opposite direction from the USB stick 102 to the personal computer 101 ... transmitted ... to the data memory 108 in the personal computer 101 [receive the encrypted data from the second unit]”) the first cryptography unit is configured to decrypt the received encrypted second data, ([para. 0076] “the personal computer 101 have a respective logic unit ... to carry out an asymmetric encryption method [decryption – see para. 0056 where decrypting data is an RSA/asymmetric encryption method]”; [para. 0121] “the decryption in the personal computer 101”) and the first memory device is configured to store the decrypted received second data. ([Para. 0121] “data [the decrypted encrypted second data] which is to be shifted [configured to store] ... to the data memory 108 [first memory device] in the personal computer 101”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include the second arithmetic processing device includes an OTP area in which rewriting of a program is not possible, and the second acquisition unit and the startup execution unit are stored in the OTP area. One of ordinary skill in the art would have been motivated to make this modification because the procedure described carries out the operation of "shifting" of data more securely than the conventional procedures. (Luft, para. 0152)
As per claim 23, Klapman in view of Luft teaches claim 18.
Klapman in view of Luft does not clearly teach wherein the first cryptography unit includes a first cryptography module and a second cryptography module and/or the second cryptography unit includes a third cryptography module and a fourth cryptography module, wherein the first cryptography module and the third cryptography module are configured to encrypt data to be sent and the second cryptography module and the fourth cryptography module are configured to decrypt data to be received.
However, Luft teaches wherein the first cryptography unit ([Luft, para. 0070] “the personal computer 101 has a crypto-logic unit 107, which may be in the form of software or in the form of a dedicated crypto-controller [first cryptography unit]”) includes a first cryptography module and a second cryptography module ([para. 0076] “the crypto-logic unit 107 ... to carry out an asymmetric encryption”; [para. 0055] “The encrypting unit [first cryptography module] can be configured to encrypt data using the RSA encryption method”; [para. 0056] “the decrypting unit [second cryptography module] can be configured to decrypt the data using the RSA encryption method”; [para. 0098] “The encryption is carried out in the crypto-logic unit 107 in the personal computer 101”; [para. 0121] “the decryption in the personal computer 101”) and/or (in accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, both limitations are disclosed) the second cryptography unit ([para. 0071] “a crypto-logic unit 115 is provided in the USB stick 102 and may be in the form of software or a dedicated crypto-controller [second cryptography unit]”) includes a third cryptography module and a fourth cryptography module, ([para. 0076] “the crypto-logic unit 107 ... to carry out an asymmetric encryption”; [para. 0055] “The encrypting unit [first cryptography module] can be configured to encrypt data using the RSA encryption method”; [para. 0056] “the decrypting unit [second cryptography module] can be configured to decrypt the data using the RSA encryption method”; [para. 0106] “The encrypted data E is decrypted by the crypto-logic unit 115 in the USB stick 102”; [para. 0121] “the encryption is carried out in the USB stick 102”) wherein the first cryptography module and the third cryptography module are configured to encrypt data to be sent and ([para. 0055] “The encrypting unit [first/third cryptography module] can be configured to encrypt data”; [para. 0080] “The encrypted data 504 which is to be shifted is transmitted in a shift message”) the second cryptography module and the fourth cryptography module are configured to decrypt data to be received. ([para. 0055] “the decrypting unit [second/fourth cryptography module] can be configured to decrypt the data”; [para. 0081] “Once the shift message has been received in the USB stick 102, the encrypted data 504 which is to be shifted is determined from the shift message and is decrypted (block 506) ... for the USB stick 102 on the basis of the asymmetric encryption method being used”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman and Luft for the same reasons as disclosed above.
As per claim 24, Klapman teaches a control device, comprising: ([Klapman, para. 0003] “a data centre [a control device, such as a micro data center]”)
at least one data processing device including: ([Klapman, para. 0003] “Host computer system ... a server [data processing device] in a data centre [a control device, such as a micro data center]”)
at least a first computing unit and a second computing unit, ([Klapman, para. 0121] “data storage device (DSD) [computing unit as it a device/unit located within the server/computer] ... located within host computer system”; [para. 0150] “two DSDs ... the first DSD .... second DSD”)
wherein the first computing unit includes a first memory device configured to provide first data to be sent, ([Klapman, para. 0122] “DSD ... comprises a controller 206”’; [para. 0150] “Controller 206 ... to send ... encrypted data to the first DSD”) a first cryptography unit configured to encrypt the first data to be sent, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of an encryption ... algorithm”; [para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data”)
wherein the second computing unit includes a second cryptography unit configured to decrypt the received encrypted first data, and ([Klapman, para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of ... decryption algorithm”; [para. 0150] “The first DSD ... to decrypt the data”) a second memory device which is configured to store the received decrypted first data. ([Para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
Klapman does not clearly teach a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit.
However, Luft teaches a first serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0070] “The personal computer 101 has a USB interface 103”) configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
wherein the second computing unit includes a second serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0071] “The USB stick 102 likewise has a USB interface 111”) configured to receive the encrypted first data from the first computing unit. ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit. One of ordinary skill in the art would have been motivated to make this modification because an attack on the interfaces is made considerably more difficult, or is even prevented. (Luft, para. 0153)
As per claim 25, Klapman teaches a method for operating a data processing device, ([Klapman, para. 0130] “The program code stored on program memory 209 enables controller 206 to receive, interpret, and execute commands received from host computer system 201 [a data processing device]”; [para. 0162] “a method ... for storing data in DSD [operating a data processing device as the DSD is within the data processing device]”) the data processing device including at least a first computing unit and a second computing unit, ([para. 0121] “data storage device (DSD) [computing unit as it a device/unit located within the server/computer] ... located within host computer system”; [para. 0150] “two DSDs ... the first DSD .... second DSD”) wherein the first computing unit includes a first memory device configured to provide first data to be sent, ([para. 0122] “DSD ... comprises a controller 206”’; [para. 0150] “Controller 206 ... to send ... encrypted data to the first DSD”) a first cryptography unit configured to encrypt the first data to be sent, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of an encryption ... algorithm”; [para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data”) wherein the second computing unit includes a second cryptography unit configured to decrypt the received encrypted first data, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of ... decryption algorithm”; [para. 0150] “The first DSD ... to decrypt the data”) a second memory device which is configured to store the received decrypted first data, the method comprising the following steps: ([para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
performing:
(i) providing the first data to be sent using the first memory device, encrypting the first data to be sent using the first cryptography unit ([Klapman, para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data ... sends the encrypted data to the first DSD”); and/or (ii) receiving the first encrypted data, (in accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious)
decrypting the received first encrypted data using a second cryptography unit, and ([Klapman, para. 0150] “The first DSD can then ... decrypt the data”)
storing the decrypted received first data using a second memory device. ([Klapman, para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
Klapman does not clearly teach a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit, (i) sending the encrypted first data using a first serial communication interface; and/or (ii) receiving the first encrypted data using the second serial communication interface.
However, Luft teaches a first serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0070] “The personal computer 101 has a USB interface 103”) configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”) wherein the second computing unit includes a second serial communication interface ([para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0071] “The USB stick 102 likewise has a USB interface 111”) configured to receive the encrypted first data from the first computing unit, ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
(i) sending the encrypted first data using a first serial communication interface; ([Luft, para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit]”) and/or (ii) (in accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, both limitations are disclosed) receiving the first encrypted data using the second serial communication interface. ([Para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0081] “the shift message has been received in the USB stick 102”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit, (i) sending the encrypted first data using a first serial communication interface; and/or (ii) receiving the first encrypted data using the second serial communication interface. One of ordinary skill in the art would have been motivated to make this modification because an attack on the interfaces is made considerably more difficult, or is even prevented. (Luft, para. 0153)
As per claim 26, Klapman in view of Luft teaches claim 25.
Klapman does not clearly teach further comprising the following steps: performing: ((i) providing second data to be sent using the second memory device, encrypting the second data to be sent using the second cryptography unit, sending the encrypted second data using the second communication interface; and/or (ii) receiving second encrypted data using the first communication interface, decrypting the received second encrypted data using the first cryptography unit, and storing the decrypted received second data using the first memory device.
However, Luft teaches further comprising the following steps:
performing:
(i) providing second data to be sent using the second memory device, ([Luft, para. 0121] “It should be noted that the transmission can also take place in the opposite direction from the USB stick 102 to the personal computer 101 ... transmitted from the data memory 116 in the USB stick 102 to the data memory 108 in the personal computer 101”)
encrypting the second data to be sent using the second cryptography unit, ([Luft, para. 0076] “the USB stick 102 have a respective logic unit ... to carry out an asymmetric encryption method”; [para. 0121] “In this case, the encryption is carried out in the USB stick”)
sending the encrypted second data using the second communication interface; ([Luft, para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data [encrypted second data] can be transmitted 119 between them”; [para. 0121] “transmission can also take place in the opposite direction from the USB stick 102 [the second communication interface to send] to the personal computer 101 [to the first computing unit] ... transmitted from the data memory 116 in the USB stick 102”)
and/or (in accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, both limitations are disclosed) (ii) receiving second encrypted data using the first communication interface, ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, [first communication interface] 111, such that data can be transmitted 119 between them”; [para. 0121] “transmission can also take place in the opposite direction from the USB stick 102 to the personal computer 101 ... transmitted ... to the data memory 108 in the personal computer 101 [receive the encrypted data from the second unit]”)
decrypting the received second encrypted data using the first cryptography unit, and ([para. 0076] “the personal computer 101 have a respective logic unit ... to carry out an asymmetric encryption method [decryption – see para. 0056 where decrypting data is an RSA/asymmetric encryption method]”; [para. 0121] “the decryption in the personal computer 101”)
storing the decrypted received second data using the first memory device. ([Para. 0121] “data [the decrypted encrypted second data] which is to be shifted [configured to store] ... to the data memory 108 [first memory device] in the personal computer 101”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman and Luft for the same reasons as disclosed above.
As per claim 31, Klapman teaches a non-transitory computer-readable medium on which is stored a computer program for operating a data processing device, ([Klapman, para. 0130] “The program code stored on program memory 209 enables controller 206 to receive, interpret, and execute commands received from host computer system 201 [a data processing device]”; [para. 0162] “a method ... for storing data in DSD [operating a data processing device as the DSD is within the data processing device] implemented in program code that is stored in ... a non-transitory computer readable medium”) the data processing device including at least a first computing unit and a second computing unit, ([para. 0121] “data storage device (DSD) [computing unit as it a device/unit located within the server/computer] ... located within host computer system”; [para. 0150] “two DSDs ... the first DSD .... second DSD”) wherein the first computing unit includes a first memory device configured to provide first data to be sent, ([para. 0122] “DSD ... comprises a controller 206”’; [para. 0150] “Controller 206 ... to send ... encrypted data to the first DSD”) a first cryptography unit configured to encrypt the first data to be sent, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of an encryption ... algorithm”; [para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data”) wherein the second computing unit includes a second cryptography unit configured to decrypt the received encrypted first data, and ([para. 0122] “controller 206 comprises dedicated hardware circuitry 210 [first cryptography unit] to perform cryptographic function, such as a hardware implementation of ... decryption algorithm”; [para. 0150] “The first DSD ... to decrypt the data”) a second memory device which is configured to store the received decrypted first data, the computer program, when executed by the data processing device, causing the data processing device to perform the following steps: ([para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
performing:
(i) providing the first data to be sent using the first memory device, encrypting the first data to be sent using the first cryptography unit; ([Klapman, para. 0150] “The second DSD controls the integrated hardware circuitry to encrypt data ... sends the encrypted data to the first DSD”); and/or (ii) receiving the first encrypted data, (in accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious)
decrypting the received first encrypted data using a second cryptography unit, and ([Klapman, para. 0150] “The first DSD can then ... decrypt the data”)
storing the decrypted received first data using a second memory device. ([Klapman, para. 0164] “DSD ... comprising means 901 ... such as a magnetic hard disk ... a solid state drive [memory device] ... for storing multiple file system data objects ... storing and decrypt data stored on the means 901 for storing)
Klapman does not clearly teach a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit, (i) sending the encrypted first data using a first serial communication interface; and/or (ii) receiving the first encrypted data using the second serial communication interface.
However, Luft teaches a first serial communication interface ([Luft, para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0070] “The personal computer 101 has a USB interface 103”) configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”) wherein the second computing unit includes a second serial communication interface ([para. 0035] “a serial interface connection ... USB ... provided as a wire-based communication link”; [para. 0071] “The USB stick 102 likewise has a USB interface 111”) configured to receive the encrypted first data from the first computing unit, ([para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit] in general from the first memory device, to the USB stick 102 [to the second computing unit]”)
(i) sending the encrypted first data using a first serial communication interface; ([Luft, para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0080] “The encrypted data 504 [encrypted first data] which is to be shifted is transmitted in a shift message ... from the personal computer 101, [from the first computing unit]”) and/or (ii) receiving the first encrypted data using the second serial communication interface. ([Para. 0072] “The personal computer 101 and the USB stick 102 are connected by means of their respective USB interface 103, 111, such that data can be transmitted 119 between them”; [para. 0081] “the shift message has been received in the USB stick 102”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include a first serial communication interface configured to send the encrypted first data to be sent from the first computing unit to the second computing unit, and wherein the second computing unit includes a second serial communication interface configured to receive the encrypted first data from the first computing unit, (i) sending the encrypted first data using a first serial communication interface; and/or (ii) receiving the first encrypted data using the second serial communication interface. One of ordinary skill in the art would have been motivated to make this modification because an attack on the interfaces is made considerably more difficult, or is even prevented. (Luft, para. 0153)
Claims 19-20 and 27-28 are rejected under 35 U.S.C. 103 as being unpatentable over Klapman in view of Luft as applied to claims 17-18 and 25-26 above and further in view of Ikeuchi et al. (US Pub. 2008/0148072) (hereinafter “Ikeuchi”).
As per claim 19, Klapman in view of Luft teaches claim 18.
Klapman does not clearly teach wherein the first memory device is configured to temporarily store the encrypted first data to be sent prior to sending and/or to temporarily store the encrypted second data received from the second computing unit prior to decryption and/or the second memory device is configured to temporarily store the encrypted second data to be sent prior to sending and/or to temporarily store the encrypted first data received from the first computing unit prior to decryption.
However, Luft teaches wherein the first/second memory device is configured to temporarily store the encrypted first/second data. ([Luft, para. 0028] “The stored data which is to be shifted [encrypted first/second data] is deleted from the ... memory [first/second memory configured to temporarily store] once the data ... is to be shifted”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman with the teachings of Luft to include wherein the first memory device is configured to temporarily store the encrypted first/second data. One of ordinary skill in the art would have been motivated to make this modification because to provide the benefit of saving memory space. (Luft, para. 0063)
Klapman in view of Luft does not clearly teach wherein the first memory device is configured to temporarily store the encrypted first data to be sent prior to sending and/or to temporarily store the encrypted second data received from the second computing unit prior to decryption and/or the second memory device is configured to temporarily store the encrypted second data to be sent prior to sending and/or to temporarily store the encrypted first data received from the first computing unit prior to decryption.
However, Ikeuchi teaches wherein the first memory device is configured to temporarily store the encrypted first data to be sent prior to sending ([Ikeuchi, Fig. 1; para. 0049] Figure 1 shows CM0 [a first memory device] and CM1[a second memory device] “as shown in FIG. 1, a code buffer 14a [a buffer in CM0/first memory device] that stores therein encrypted data [temporarily store the encrypted first data as it is in a buffer]”; [para. 0051] “encrypts the unencrypted data to predetermined encrypted data ... and transmits the encrypted data to a code buffer 24a [making the temporarily store prior to the sending]”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) to temporarily store the encrypted second data received from the second computing unit prior to decryption ([para. 0127] “write the local data stored in the local area of the CM1 [received from the second computing unit] in the local area of the CM0 [temporarily store the encrypted second data from the second memory device in the first memory device]”; [para. 0130] “when there is a failure in other encryption buffers 14b ... the decrypting process [prior to decryption] ... performed by using the mirror data corresponding to the local data”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) the second memory device is configured to temporarily store the encrypted second data ([Fig. 1; para. 0051] “encrypted data ... a code buffer 24a [temporarily store the encrypted second data]”) to be sent prior to sending ([para. 0127] “write [sending] the local data stored in the local area of the CM1 [encrypted second data stored in the second memory device] in the local area of the CM0 [to be sent, and thus making the storing necessarily prior to the sending]”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) to temporarily store the encrypted first data received from the first computing unit ([Fig. 1; para. 0049] “as shown in FIG. 1, a code buffer 14a [first computing unit] that stores therein encrypted data”; [para. 0051] “encrypts the unencrypted data ... and transmits [encrypted first data received from the first computing unit] the encrypted data to a code buffer 24a [store the encrypted first data”) prior to decryption. ([Para. 0130] “decryption process ... using the mirror data corresponding to the local data [code buffer 24a as it is the mirror/duplicated data – see Fig. 1]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman in view of Luft with the teachings of Ikeuchi to include wherein the first memory device is configured to temporarily store the encrypted first data to be sent prior to sending and/or to temporarily store the encrypted second data received from the second computing unit prior to decryption and/or the second memory device is configured to temporarily store the encrypted second data to be sent prior to sending and/or to temporarily store the encrypted first data received from the first computing unit prior to decryption. One of ordinary skill in the art would have been motivated to make this modification because by doing so, the data is made redundant and the data is hardly lost. (Ikeuchi, para. 0094)
As per claim 20, Klapman in view of Luft teaches claim 17.
Klapman in view of Luft does not clearly teach wherein the first memory device is configured to store the unencrypted first data to be sent and the encrypted first encrypted data to be sent in different areas in the first memory device and/or the second memory device is configured to store the received encrypted first data and the unencrypted received first data in different areas in the second memory device.
However, Ikeuchi teaches wherein the first memory device is configured to store the unencrypted first data to be sent and ([Ikeuchi, Fig. 2] the encryption buffer 14b stores unencrypted data to be sent; [para. 0049] “an encryption buffer 14b that stores therein unencrypted data”) the encrypted first encrypted data to be sent in different areas in the first memory device ([Fig. 1] the code buffer 14a stores encrypted data to be sent; [para. 0049] “a code buffer 14a that stores therein encrypted data”) and/or the second memory device is configured to store the received encrypted first data and the unencrypted received first data in different areas in the second memory device. ([Para. 0051] “encrypts the unencrypted data to predetermined encrypted data ... Specifically, the storage 10 duplicates the unencrypted data in the encryption buffer 14b to an encryption buffer 24b [receive unencrypted first data] in a controller module (CM) 1 [the second memory device], encrypts the unencrypted data to predetermined encrypted data, and transmits the encrypted data to a code buffer 24a [receive unencrypted first data]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman in view of Luft with the teachings of Ikeuchi to include wherein the first memory device is configured to store the unencrypted first data to be sent and the encrypted first encrypted data to be sent in different areas in the first memory device and/or the second memory device is configured to store the received encrypted first data and the unencrypted received first data in different areas in the second memory device. One of ordinary skill in the art would have been motivated to make this modification because the time for encrypting or decrypting the data can be reduced. (Ikeuchi, para. 0093)
As per claim 27, Klapman in view of Luft teaches claim 26.
Klapman does not clearly teach wherein: (i) the first memory device temporarily stores the encrypted first data to be sent prior to sending and/or temporarily stores the encrypted second data received from the second computing unit prior to decryption and/or the second memory device temporarily stores the encrypted second data to be sent prior to sending and/or temporarily stores the encrypted first data received from the first computing unit prior to decryption.
However, Luft teaches wherein the first/second memory device is configured to temporarily store the encrypted first/second data. ([Luft, para. 0028] “The stored data which is to be shifted [encrypted first/second data] is deleted from the ... memory [first/second memory configured to temporarily store] once the data ... is to be shifted”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman and Luft for the same reasons as disclosed above.
Klapman in view of Luft does not clearly teach wherein: (i) the first memory device temporarily stores the encrypted first data to be sent prior to sending and/or temporarily stores the encrypted second data received from the second computing unit prior to decryption and/or the second memory device temporarily stores the encrypted second data to be sent prior to sending and/or temporarily stores the encrypted first data received from the first computing unit prior to decryption.
However, Ikeuchi teaches wherein: (i) the first memory device temporarily stores the encrypted first data to be sent prior to sending ([Ikeuchi, Fig. 1; para. 0049] Figure 1 shows CM0 [a first memory device] and CM1[a second memory device] “as shown in FIG. 1, a code buffer 14a [a buffer in CM0/first memory device] that stores therein encrypted data [temporarily store the encrypted first data as it is in a buffer]”; [para. 0051] “encrypts the unencrypted data to predetermined encrypted data ... and transmits the encrypted data to a code buffer 24a [making the temporarily store prior to the sending]”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) temporarily stores the encrypted second data received from the second computing unit prior to decryption ([para. 0127] “write the local data stored in the local area of the CM1 [received from the second computing unit] in the local area of the CM0 [temporarily store the encrypted second data from the second memory device in the first memory device]”; [para. 0130] “when there is a failure in other encryption buffers 14b ... the decrypting process [prior to decryption] ... performed by using the mirror data corresponding to the local data”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) the second memory device temporarily stores the encrypted second data ([Fig. 1; para. 0051] “encrypted data ... a code buffer 24a [temporarily store the encrypted second data]”) to be sent prior to sending ([para. 0127] “write [sending] the local data stored in the local area of the CM1 [encrypted second data stored in the second memory device] in the local area of the CM0 [to be sent, and thus making the storing necessarily prior to the sending]”) and/or (in accordance with the broadest reasonable interpretation of and/or, any of the limitations is required to be disclosed for the claim as a whole to be made obvious; here, all the limitations are disclosed) temporarily stores the encrypted first data received from the first computing unit ([Fig. 1; para. 0049] “as shown in FIG. 1, a code buffer 14a [first computing unit] that stores therein encrypted data”; [para. 0051] “encrypts the unencrypted data ... and transmits [encrypted first data received from the first computing unit] the encrypted data to a code buffer 24a [store the encrypted first data”) prior to decryption. ([Para. 0130] “decryption process ... using the mirror data corresponding to the local data [code buffer 24a as it is the mirror/duplicated data – see Fig. 1]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman, Luft and Ikeuchi for the same reasons as disclosed above.
As per claim 28, Klapman in view of Luft teaches claim 25.
Klapman in view of Luft does not clearly teach wherein the first memory device stores the unencrypted first data to be sent and the encrypted first data to be sent in different areas in the first memory device and/or the second memory device stores the received encrypted first data and the unencrypted received first data in different areas in the second memory device.
However, Ikeuchi teaches wherein the first memory device stores the unencrypted first data to be sent and ([Ikeuchi, Fig. 2] the encryption buffer 14b stores unencrypted data to be sent; [para. 0049] “an encryption buffer 14b that stores therein unencrypted data”) the encrypted first data to be sent in different areas in the first memory device ([Fig. 1] the code buffer 14a stores encrypted data to be sent; [para. 0049] “a code buffer 14a that stores therein encrypted data”) and/or the second memory device stores the received encrypted first data and the unencrypted received first data in different areas in the second memory device. ([Para. 0051] “encrypts the unencrypted data to predetermined encrypted data ... Specifically, the storage 10 duplicates the unencrypted data in the encryption buffer 14b to an encryption buffer 24b [receive unencrypted first data] in a controller module (CM) 1 [the second memory device], encrypts the unencrypted data to predetermined encrypted data, and transmits the encrypted data to a code buffer 24a [receive unencrypted first data]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman, Luft and Ikeuchi for the same reasons as disclosed above.
Claims 21-22 and 29-30 are rejected under 35 U.S.C. 103 as being unpatentable over Klapman in view of Luft as applied to claims 17-18 and 25-26 above and further in view of Wang et al. (US Pub. 2023/0269074) (hereinafter “Wang”).
As per claim 21, Klapman in view of Luft teaches 17.
Klapman in view of Luft does not clearly teach wherein the first communication interface is configured to send a set of first data to be encrypted and sent only when the set of first data to be encrypted and sent has been completely encrypted by the first cryptography unit and/or the second cryptography unit is configured to decrypt a received set of first data to be decrypted only when the received set of first data to be decrypted has been completely received by the second communication interface.
However, Wang teaches wherein the first communication interface is configured to send a set of first data to be encrypted and sent only when the set of first data to be encrypted and sent has been completely encrypted by the first cryptography unit and/or (In accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious) the second cryptography unit ([Wang, Fig. 16; para. 0167] “Optionally ... one ... encryption/decryption systems [second cryptography unit] are deployed”) is configured to decrypt a received set of first data to be decrypted only when the received set of first data to be decrypted has been completely received by the second communication interface. ([para. 0100] “if the encryption/decryption component 1 [second cryptography unit] includes one decryption channel 112, before decrypting a plurality of ciphertext physical layer data streams, the decryption channel 112 needs to align the plurality of ciphertext physical layer data streams, and after the alignment, decrypt the plurality of ciphertext physical layer data streams ... alignment means ensuring, before decryption, that data blocks [set of first data] of a plurality of ciphertext physical layer data streams are completely received [only when the received set of first data to be decrypted has been completely received]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to have modified the elements disclosed by Klapman in view of Luft with the teachings of Wang to include wherein the first communication interface is configured to send a set of first data to be encrypted and sent only when the set of first data to be encrypted and sent has been completely encrypted by the first cryptography unit and/or the second cryptography unit is configured to decrypt a received set of first data to be decrypted only when the received set of first data to be decrypted has been completely received by the second communication interface. One of ordinary skill in the art would have been motivated to make this modification because in this way, the data can be accurately decrypted. (Wang, para. 0029)
As per claim 22, Klapman in view of Luft teaches 18.
Klapman in view of Luft does not clearly teach wherein the second communication interface is configured to send a set of second data to be encrypted and sent only when the set of second data to be encrypted and sent has been completely encrypted by the second cryptography unit and/or the first cryptography unit is configured to decrypt a received set of second data to be decrypted only when the received set of second data to be decrypted has been completely received by the first communication interface.
However, Wang teaches wherein the second communication interface is configured to send a set of second data to be encrypted and sent only when the set of second data to be encrypted and sent has been completely encrypted by the second cryptography unit and/or (In accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious) the first cryptography unit is ([Wang, Fig. 16; para. 0167] “Optionally ... more ... encryption/decryption systems [first cryptography unit] are deployed”) configured to decrypt a received set of second data to be decrypted only when the received set of second data to be decrypted has been completely received by the first communication interface. ([Para. 0100] “if the encryption/decryption component 1 [first cryptography unit] includes one decryption channel 112, before decrypting a plurality of ciphertext physical layer data streams, the decryption channel 112 needs to align the plurality of ciphertext physical layer data streams, and after the alignment, decrypt the plurality of ciphertext physical layer data streams ... alignment means ensuring, before decryption, that data blocks of a plurality of ciphertext physical layer data streams are completely received [only when the received set of second data to be decrypted has been completely received]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman, Luft and Wang for the same reasons as disclosed above.
As per claim 29, Klapman in view of Luft teaches 25.
Klapman in view of Luft does not clearly teach wherein: (i) the first communication interface sends a set of first data to be encrypted and sent only when the set of first data to be encrypted and sent has been completely encrypted by the first cryptography unit and/or (ii) the second cryptography unit decrypts a received set of first data to be decrypted only when the received set of first data to be decrypted has been completely received by the second communication interface.
However, Wang teaches wherein: (i) the first communication interface sends a set of first data to be encrypted and sent only when the set of first data to be encrypted and sent has been completely encrypted by the first cryptography unit and/or (In accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious) (ii) the second cryptography unit [Wang, Fig. 16; para. 0167] “Optionally ... one ... encryption/decryption systems [second cryptography unit] are deployed”) decrypts a received set of first data to be decrypted only when the received set of first data to be decrypted has been completely received by the second communication interface. ([para. 0100] “if the encryption/decryption component 1 [second cryptography unit] includes one decryption channel 112, before decrypting a plurality of ciphertext physical layer data streams, the decryption channel 112 needs to align the plurality of ciphertext physical layer data streams, and after the alignment, decrypt the plurality of ciphertext physical layer data streams ... alignment means ensuring, before decryption, that data blocks [set of first data] of a plurality of ciphertext physical layer data streams are completely received [only when the received set of first data to be decrypted has been completely received]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman, Luft and Wang for the same reasons as disclosed above.
As per claim 30, Klapman in view of Luft teaches 26.
Klapman in view of Luft does not clearly teach wherein: (i) the second communication interface sends a set of second data to be encrypted and sent only when the set of second data to be encrypted and sent has been completely encrypted by the second cryptography unit and/or (ii) the first cryptography unit decrypts a received set of second data to be decrypted only when the received set of second data to be decrypted has been completely received by the first communication interface.
However, Wang teaches wherein: (i) the second communication interface sends a set of second data to be encrypted and sent only when the set of second data to be encrypted and sent has been completely encrypted by the second cryptography unit and/or (In accordance with the broadest reasonable interpretation of and/or, either one of the limitations is required to be disclosed for the claim as a whole to be made obvious) (ii) the first cryptography unit ([Wang, Fig. 16; para. 0167] “Optionally ... more ... encryption/decryption systems [first cryptography unit] are deployed”) decrypts a received set of second data to be decrypted only when the received set of second data to be decrypted has been completely received by the first communication interface. ([Para. 0100] “if the encryption/decryption component 1 [first cryptography unit] includes one decryption channel 112, before decrypting a plurality of ciphertext physical layer data streams, the decryption channel 112 needs to align the plurality of ciphertext physical layer data streams, and after the alignment, decrypt the plurality of ciphertext physical layer data streams ... alignment means ensuring, before decryption, that data blocks of a plurality of ciphertext physical layer data streams are completely received [only when the received set of second data to be decrypted has been completely received]”)
It would have been obvious before the effective filing date of the claimed invention for one of ordinary skill in the art to combine the teachings of Klapman, Luft and Wang for the same reasons as disclosed above.
Conclusion
The prior art made of record and not relied upon is considered pertinent to applicant's disclosure:
Shanbhogue et al. (US Pub. 2020/0296099) discloses link protection for trusted I/O devices where an SoC encrypts data to be transmitted to a device where the transmitted data is decrypted and the link is by a serial link.
Rogers et al. (US Pub. 2023/0094125) discloses a secure and unsecure area in system memory for storing data and different computer units for decrypting and encrypting data.
Hueber et al. (US Patent No. 9,246,886) discloses a device for handling of sensitive data that includes a primary ASCI and a second ASIC, where both ASCI includes encryption/decryption units in each respective ASCI and encrypted data content is transmitted by the second ASCI to the primary ASCI.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to ZHE LIU whose telephone number is (571) 272-3634. The examiner can normally be reached on Monday - Friday: 8:30 AM to 5:30 PM.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Carl Colin can be reached on (571) 272-3862. The fax phone number for the organization where this application or proceeding is assigned is (571) 273-8300.
Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at (866) 217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call (800) 786-9199 (IN USA OR CANADA) or (571) 272-1000.
/ZHE LIU/Examiner, Art Unit 2493